Daily digest
Monday 20 April 2026
A quiet day: only 20 new CVEs against a recent average of about 42. Of those, 5 high. agentscope was the most-affected vendor with 4.
New this day, ranked by depth score
The 12 that matter most of the 20 published.
CVE-2026-6606High· 7.3AgentScope vulnerable to Server-Side Request Forgery
AgentScope vulnerable to Server-Side Request Forgery
CVE-2026-6605High· 7.3AgentScope vulnerable to Server-Side Request Forgery
AgentScope vulnerable to Server-Side Request Forgery
CVE-2026-6604High· 7.3AgentScope vulnerable to Server-Side Request Forgery
AgentScope vulnerable to Server-Side Request Forgery
CVE-2026-6603High· 7.3AgentScope Vulnerable to Remote Code Injection
AgentScope Vulnerable to Remote Code Injection
CVE-2026-6596High· 7.3Langflow: DoS Through Lack of File Size Restriction via Deprecated Unauthenticated File Upload API
Langflow: DoS Through Lack of File Size Restriction via Deprecated Unauthenticated File Upload API
CVE-2026-6634Medium· 6.3Memos has an Incorrect Privilege Assignment issue
Memos has an Incorrect Privilege Assignment issue
CVE-2026-6599Medium· 6.3Langflow vulnerable to injection
Langflow vulnerable to injection
CVE-2026-6587Medium· 6.3A security flaw has been discovered in vibrantlabsai RAGAS up to 0.4.3
A security flaw has been discovered in vibrantlabsai RAGAS up to 0.4.3. The affected element is the function _try_process_local_file/_try_process_url of the file src/ragas/metrics/collections/multi_modal_faithfulness/util.py of the compo…
CVE-2026-41245Medium· 5.9Junrar is an open source java RAR archive library
Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content into sibling directories wh…
CVE-2026-6608Medium· 5.3FastChat has a Content Moderation Bypass via Arena Side-by-Side Views
FastChat has a Content Moderation Bypass via Arena Side-by-Side Views
CVE-2026-6607Medium· 5.3FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426)
FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426)
CVE-2025-66335Medium· 5.3Apache Doris MCP Server vulnerable to SQL Injection via improper query context neutralization
Apache Doris MCP Server vulnerable to SQL Injection via improper query context neutralization
Most-affected vendors
By CVEs published in the period.